远行商人库存查询

Security checks across malware telemetry and agentic risk

Overview

This skill appears to fetch a game merchant inventory from a disclosed API using a user-provided API key, without hidden persistence or unrelated local access.

Install only if you trust the publisher and the wegame.shallow.ink API service. Use an API key you are allowed to use, prefer a local secret or environment variable over putting the key directly in shared chat or command history, and avoid sharing logs that may contain the key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill documentation indicates use of both environment variables and outbound network access, but no permissions are declared. This creates a transparency and trust problem: a user or hosting platform may not realize the skill can read secrets such as ROCOM_API_KEY and transmit data to a remote service, which increases the risk of unintended secret exposure or policy bypass.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal